{"id":6669,"date":"2018-08-20T14:25:25","date_gmt":"2018-08-20T12:25:25","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=6669"},"modified":"2019-03-23T23:40:53","modified_gmt":"2019-03-23T22:40:53","slug":"sql-server-2016-sp2-update-kb4293807-pulled","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2018\/08\/20\/sql-server-2016-sp2-update-kb4293807-pulled\/","title":{"rendered":"SQL Server 2016 SP2: Update KB4293807 pulled"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline; border-width: 0px;\" title=\"Update\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/02\/Update.jpg\" alt=\"Windows Update\" width=\"54\" height=\"54\" align=\"left\" border=\"0\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2018\/08\/20\/sql-server-2016-sp2-update-kb4293807-zurckgezogen\/\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]A brief information for administrators: Microsoft released the security update KB4293807 for SQL Server 2016 SP2 on August 14, 2018. But this update has already been pulled.\u00a0<strong>Addendum:<\/strong>\u00a0Update revision\u00a0<a href=\"https:\/\/support.microsoft.com\/de-de\/help\/4458621\" target=\"_blank\" rel=\"noopener noreferrer\">KB4458621<\/a>\u00a0has been released on August 19, 2018.<\/p>\n<p><!--more--><\/p>\n<h2>Update KB4293807 for SQL Server 2016 SP2<\/h2>\n<p>Update <a href=\"https:\/\/support.microsoft.com\/en-us\/help\/4293807\/description-of-the-security-update-for-the-remote-code-execution-vulne\" target=\"_blank\" rel=\"noopener noreferrer\">KB4293807<\/a> for SQL Server 2016 SP2 has been released on August 14, 2018. The kb article is titled <em>Description of the security update for the Remote Code Execution vulnerability in SQL Server 2016 SP2 (CU): August 14, 2018<\/em>, and says:<\/p>\n<blockquote><p>A buffer overflow vulnerability <a href=\"https:\/\/portal.msrc.microsoft.com\/en-us\/security-guidance\/advisory\/CVE-2018-8273\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2018-8273<\/a> exists in the Microsoft SQL Server that could allow remote code execution on an affected system. An attacker who successfully exploits this vulnerability could execute code in the context of the SQL Server Database Engine service account.<\/p><\/blockquote>\n<p>However, an attacker must submit a specially crafted query to an affected SQL server to exploit the vulnerability. This may allow remote code execution on an affected system. Hence the security update distributed via Windows Update. It was also available in the download center.<\/p>\n<h2>Install error 0x80070643, update pulled<\/h2>\n<p>German blog reader Axel H. contacted me via e-mail and informed me about his experience with this update.<\/p>\n<blockquote><p>Enclosed, if you are interested, my SQL Server security update issue this weekend. It could not be installed, ended with Error 0x80070643.<\/p>\n<p>When I wanted to do this again today, I was allowed to notice that it was withdrawn. :-)<\/p><\/blockquote>\n<p>Error code 0x80070643 is hilarious, it stands for ERROR_INSTALL_FAILURE. The description says: 'Serious error during installation'.<\/p>\n<p><img decoding=\"async\" title=\"Update KB4293807 pulled\" src=\"https:\/\/i.imgur.com\/plLl3dt.jpg\" alt=\"Update KB4293807 pulled\" \/><\/p>\n<p>It seems that the observation published above havsn't been an isolated case, because Microsoft has pulled this update. If you visit the download page for update KB4293807, you will see the above message.<\/p>\n<blockquote><p><strong>Note:<\/strong> Microsoft has published a MSDN\u00a0<a href=\"https:\/\/web.archive.org\/web\/20190306233501\/https:\/\/blogs.msdn.microsoft.com\/sqlreleaseservices\/issue-with-security-update-for-the-remote-code-execution-vulnerability-in-sql-server-2016-sp2-cu-august-14-2018\/\" target=\"_blank\" rel=\"noopener noreferrer\">blog post<\/a>\u00a0where they say: If the update causes issues, uninstall it. They are planning a replacement update (KB4458621). Read also the comments the MSDN blog post received.<\/p>\n<p><strong>Addendum:<\/strong>\u00a0Update revision\u00a0<a href=\"https:\/\/support.microsoft.com\/de-de\/help\/4458621\" target=\"_blank\" rel=\"noopener noreferrer\">KB4458621<\/a>\u00a0has been released on August 19, 2018. <a href=\"https:\/\/web.archive.org\/web\/20190112111836\/https:\/\/blogs.msdn.microsoft.com\/sqlreleaseservices\/resolved-issue-with-security-update-for-the-remote-code-execution-vulnerability-in-sql-server-2016-sp2-cu-august-14-2018\/\" target=\"_blank\" rel=\"noopener noreferrer\">see here<\/a><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>[German]A brief information for administrators: Microsoft released the security update KB4293807 for SQL Server 2016 SP2 on August 14, 2018. But this update has already been pulled.\u00a0Addendum:\u00a0Update revision\u00a0KB4458621\u00a0has been released on August 19, 2018.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,22],"tags":[1578,4,1577,1576],"class_list":["post-6669","post","type-post","status-publish","format-standard","hentry","category-security","category-update","tag-0x80070643","tag-error","tag-kb4293807","tag-sql-server-2016-sp2-update"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/6669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=6669"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/6669\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=6669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=6669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=6669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}